Shai-Hulud is a self-propagating JavaScript supply-chain worm targeting the npm ecosystem and Node.js developer and CI/CD environments. It executes through malicious package-install lifecycle logic in compromised package releases, harvests package-registry tokens, GitHub credentials, cloud-provider secrets, CI/CD secrets, SSH material, and other developer credentials, and exfiltrates collected data through attacker-controlled public code repositories. Recovered publishing credentials are used to modify, version, and republish additional packages, enabling recursive propagation through maintainers, downstream developers, and build systems. Reported variants use obfuscated staged payloads, secret-scanning tooling, and persistence mechanisms affecting Linux and macOS developer environments. Some later variants include a destructive fallback when credential theft or propagation fails. The original 2025 Shai-Hulud activity has no confirmed attribution. Later cloned and Mini Shai-Hulud campaigns have been associated with the TeamPCP cybercrime ecosystem, although public release of the worm framework permits independent reuse by other actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-10894 highlights how a single workflow misconfiguration can cascade into widespread compromise across the JavaScript ecosystem. The attack chain for CVE-2025-10894 began with exploitation of a GitHub Actions workflow in the Nx repository. The workflow used the pull_request_target trigger, which grants elevated permissions (including a writable GITHUB_TOKEN) to workflows running on pull requests from forks. Attackers crafted pull requests with titles containing bash injection payloads. | The campaign escalated with the release of a self-replicating worm (Shai-Hulud) that used harvested npm credentials to infect additional packages, resulting in over 500 compromised npm projects.
Shai-Hulud is a self-propagating, info-stealing malware that infects software components, uses the access to publish poisoned versions, and then harvests the repository accounts of those affected by the malware downstream.
359 GitHub repos created with encrypted stolen credentials — “Shai-Hulud: Here We Go Again.” CVE-2026-45321 published CVSS 9.6 critical. Mitre, CISA, and major registry operators issue coordinated advisories. | Shai-Hulud is, at this point, a very familiar name... The most recent one being the so-called Mini Shai-Hulud... they are back again... compromising the TanStack Router packages, and starting a brand new campaign based on Mini Shai-Hulud.
In the Shai-Hulud incident, the compromised packages (MAL-2025-46974 and CVE-2025-59144) were identified early, providing actionable findings that customers could remediate quickly.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The article references Mini Shai-Hulud supply-chain attack campaigns and notes that the public leak of the Shai-Hulud worm source code enabled other actors to adopt similar tactics.
In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
The group often uses a purpose-built, self-replicating npm worm it developed called Shai-Hulud to infect GitHub projects.
researchers say are enabling variants of the Shai-Hulud supply-chain worm to infect and compromise hundreds of software packages and developer accounts worldwide.
A new wave of the Shai-Hulud supply chain campaign, adding 23 newly discovered malicious PyPI package-version artifacts to an already alarming operation that previously compromised 37 packages.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
“The malware then leveraged those credentials to tamper with additional packages and repositories.”
“[TeamPCP] laced open source software with malware that self-propagated from one package to another... targeting organizations’ CI/CD pipelines.”
“The malware’s 1st stage obfuscated code, bundled inside the hijacked packages now contains a more obfuscated code,” using “XOR instead of ROT for deobfuscation.”
Upon locating a GitHub token, it exfiltrates everything to a new public repo... If it finds an npm token, it calls the registry’s API to list every package the compromised developer maintains.
[bundle.js] searches the infected machine for anything resembling credentials, including npm and GitHub personal access tokens, AWS or GCP secrets, and whatever it can extract from a cloud instance’s metadata service.
“The stolen information is sent encrypted to a new repository in GitHub” and the comparison table identifies a “GitHub C2” repository description and commit message.
“CloudSEK data analyzed by StepSecurity showed 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations.”
270 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm associated with supply-chain attack activity; its leaked source code reportedly enabled subsequent actors to reuse similar techniques.
A larger Shai-Hulud variant that backdoored hundreds of packages, executed earlier during installation to evade developer-trigger controls, and included destructive home-directory deletion behavior when unable to obtain credentials or propagate.
Named as the malware/campaign lineage for the Trinitite payload and as the basis for an earlier npm supply-chain attack. In this incident, its Mini Shai-Hulud variant propagates by stealing credentials and publishing altered packages using victim publishing access.
A supply-chain npm worm that compromises packages, steals credentials, and exfiltrates collected data in encrypted form to attacker-controlled GitHub repositories. This variant uses an obfuscated first-stage payload, XOR deobfuscation, AES-GCM encryption, Bun 1.4.0, and includes currently unweaponized logic to retrieve an additional C2 payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.